The OSINT Tools website
This policy covers visits to https://osinttools.me, directory browsing, favorites, tool submissions, Google sign-in and the site interfaces described below. It does not govern the OSINT tools, databases, repositories or other destinations reached through directory links.
The description is based on the current application code and configuration. Hosting platforms, network intermediaries, email providers and linked services can process data under their own terms and policies.
Activity and the data it can involve
Submissions, account details and correspondence
Browsing does not require you to type a name or email address into OSINT Tools. If you submit a tool, the site stores the website name and URL, primary and optional secondary category, description, CLI indicator, review status, submission timestamps and requesting IP address. The IP address is used to enforce a limit of three submissions per user or IP address during a 12-hour period. If you choose Google sign-in, the account fields described in section 05 are returned through Google's OAuth flow. If you send an email, the address, message body and any attachments you add are processed by the mail services involved.
Do not send passwords, authentication codes, private case files or sensitive personal data that is not needed to explain the request.
What reaches the application and its infrastructure
A web request ordinarily exposes the requesting IP address and technical headers to the server, hosting stack and network intermediaries needed to deliver the page. The application specifically reads the CF-IPCountry country header when it is supplied. If a visitor first creates a database-backed user record by saving a favorite or making a permitted unbound submission, that country code is stored with the record.
The application is configured to write file-based logs, including application and service errors. The repository does not define a retention schedule for those logs and does not establish what additional access or security logging may be configured by the hosting provider or reverse proxy.
Tool-submission records store the requesting IP address for rate limiting. The current user and favorites records do not contain an IP-address field. An IP address can also be visible to the server, network provider, analytics service or their logs.
Visitor records and Google sign-in
The favorites feature can create a user record without Google sign-in. That record uses the OSINT Tools visitor cookie as its identifier and can contain a country code, creation time and update time. Favorite records connect that user record to a tool ID and record when the favorite was added.
The site can be configured either to require Google sign-in for tool submissions or to allow submissions linked only to the visitor record. Google sign-in requests the openid, email and profile scopes. It stores the Google account identifier, email address, display name and profile image URL returned through that flow, then associates them with the site's user record. Authentication requests and account data returned by Google are also processed by Google.
Google Analytics and advertising code
Pages load Google Analytics through a site measurement ID and initialize the Google dataLayer. They also load the Google AdSense script. These requests can provide Google with network and browser information and can involve cookies or similar identifiers controlled by Google.
The OSINT Tools repository does not define Google's internal retention or advertising-profile rules. Those details are governed by Google's configuration and published policies rather than this codebase.
Leaving the directory changes who handles the request
Directory links lead to independently operated websites, repositories and services. When you follow one, the destination receives the request and may collect search terms, account details, uploaded material or other information depending on how that tool works.
This policy does not control those activities. Review the destination's terms and privacy information before submitting personal data, investigation targets, files or credentials.
External services loaded by the site
What the code fixes, and what it does not
The visitor identifier cookie is configured for ten years. The Google redirect cookie lasts one hour, and the dismissed-prompt preference lasts 24 hours. The application database stores user, Google profile, favorite and tool-submission records without a fixed deletion period in the current repository.
File-based application logs are configured, but no log rotation or retention period is specified here. Email retention depends on the mail systems involved. Third-party analytics, advertising, CDN, badge and destination providers apply their own retention rules.
Security has practical limits
OSINT Tools relies on application, database, hosting and third-party service controls to deliver the site. No web transmission, database or external provider can be represented as completely secure. Avoid sending information that is not necessary for the feature or enquiry you are using.
Controls available to visitors
- Browse without connecting a Google account.
- Remove individual favorites through the favorites interface.
- Delete or block site cookies in your browser; this can break continuity for saved favorites, unbound submissions and sign-in.
- Use the logout action to clear the visitor identifier cookie from that browser. Logging out does not itself delete existing database records.
- Review or revoke OSINT Tools access from your Google account controls.
- Use browser privacy controls for analytics, advertising and third-party assets.
Questions about a site user record or privacy request can be sent to the contact address below. Include enough information to identify the relevant record, but do not send a password or authentication code.
A general research directory, not a children's service
The site is not designed specifically for children and does not ask visitors to provide an age. If a parent or guardian believes a child has provided personal information through Google sign-in or email, they can contact the site with the relevant details.
Policy revisions
This page may be revised when site features, providers or data flows change. The date at the top records the latest published revision. Earlier wording should not be relied on to describe a newer version of the application.
Privacy questions
Send questions about this policy or a site user record to the address below. For directory content corrections, the contact guide provides a more specific report format.